Size | 1.7MB |
---|---|
Type | PE32+ executable (GUI) x86-64, for MS Windows |
MD5 | 3d8f31daa9025f13659fa3fd0f7a3c4e |
SHA1 | 263b3f7a032c15e1466deb9d17e28281b74afad9 |
SHA256 | 83bd32ac63c25e76b25610dfc4d28269425ed2c3478ed6722c627e262f6f26ac |
SHA512 |
be23c507d1c63b6d9bbdaca291eb9cb8f274f2c05d8931daf1fadfe392e2b87f3f437d2457893d96526e59609a8e1e7cd17aa37c1124eaa75a53a8858e7b3ade
|
CRC32 | 912E7461 |
ssdeep | None |
PDB Path | z:\task_1579288126\build\src\obj-firefox\toolkit\components\maintenanceservice\maintenanceservice.pdb |
Yara |
|
This file is very suspicious, with a score of 10 out of 10!
Please notice: The scoring system is currently still in development and should be considered an alpha feature.
Expecting different results? Send us this analysis and we will inspect it. Click here
Category | Started | Completed | Duration | Routing | Logs |
---|---|---|---|---|---|
FILE | May 5, 2025, 11:27 a.m. | May 5, 2025, 11:34 a.m. | 394 seconds | internet |
Show Analyzer Log Show Cuckoo Log |
2025-05-05 10:40:55,030 [analyzer] DEBUG: Starting analyzer from: C:\tmpsftntc 2025-05-05 10:40:55,030 [analyzer] DEBUG: Pipe server name: \??\PIPE\wdEySAKXerWmRaue 2025-05-05 10:40:55,030 [analyzer] DEBUG: Log pipe server name: \??\PIPE\VegUzhBMQFyHqRNVcjiFmyidWU 2025-05-05 10:40:55,390 [analyzer] DEBUG: Started auxiliary module Curtain 2025-05-05 10:40:55,390 [analyzer] DEBUG: Started auxiliary module DbgView 2025-05-05 10:40:55,890 [analyzer] DEBUG: Started auxiliary module Disguise 2025-05-05 10:40:56,125 [analyzer] DEBUG: Loaded monitor into process with pid 508 2025-05-05 10:40:56,125 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets 2025-05-05 10:40:56,125 [analyzer] DEBUG: Started auxiliary module Human 2025-05-05 10:40:56,125 [analyzer] DEBUG: Started auxiliary module InstallCertificate 2025-05-05 10:40:56,140 [analyzer] DEBUG: Started auxiliary module Reboot 2025-05-05 10:40:56,233 [analyzer] DEBUG: Started auxiliary module RecentFiles 2025-05-05 10:40:56,233 [analyzer] DEBUG: Started auxiliary module Screenshots 2025-05-05 10:40:56,233 [analyzer] DEBUG: Started auxiliary module Sysmon 2025-05-05 10:40:56,233 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n 2025-05-05 10:40:56,375 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\3d8f31daa9025f13659fa3fd0f7a3c.exe' with arguments '' and pid 324 2025-05-05 10:40:56,608 [analyzer] DEBUG: Loaded monitor into process with pid 324 2025-05-05 10:40:57,140 [analyzer] INFO: Added new file to list with pid 324 and path C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe 2025-05-05 10:40:59,578 [analyzer] INFO: Added new file to list with pid 324 and path C:\Windows\System32\alg.exe 2025-05-05 10:41:00,796 [analyzer] INFO: Added new file to list with pid 324 and path C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe 2025-05-05 10:41:01,921 [analyzer] INFO: Added new file to list with pid 324 and path C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 2025-05-05 10:41:03,467 [analyzer] INFO: Added new file to list with pid 324 and path C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe 2025-05-05 10:41:04,655 [analyzer] INFO: Added new file to list with pid 324 and path C:\Windows\System32\dllhost.exe 2025-05-05 10:41:05,858 [analyzer] INFO: Added new file to list with pid 324 and path C:\Windows\ehome\ehrecvr.exe 2025-05-05 10:41:06,875 [analyzer] INFO: Added new file to list with pid 324 and path C:\Windows\ehome\ehsched.exe 2025-05-05 10:41:07,937 [analyzer] INFO: Added new file to list with pid 324 and path C:\Windows\System32\FXSSVC.exe 2025-05-05 10:41:08,983 [analyzer] INFO: Added new file to list with pid 324 and path C:\Windows\System32\ieetwcollector.exe 2025-05-05 10:41:10,796 [analyzer] INFO: Added new file to list with pid 324 and path C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe 2025-05-05 10:30:43,127 [analyzer] INFO: Added new file to list with pid 324 and path C:\Windows\System32\msdtc.exe 2025-05-05 10:30:44,361 [analyzer] INFO: Added new file to list with pid 324 and path C:\Windows\System32\msiexec.exe 2025-05-05 10:30:45,565 [analyzer] INFO: Added new file to list with pid 324 and path C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE 2025-05-05 10:30:46,940 [analyzer] INFO: Added new file to list with pid 324 and path C:\Windows\SysWOW64\perfhost.exe 2025-05-05 10:30:48,157 [analyzer] INFO: Added new file to list with pid 324 and path C:\Windows\System32\Locator.exe 2025-05-05 10:30:49,329 [analyzer] INFO: Added new file to list with pid 324 and path C:\Windows\System32\snmptrap.exe 2025-05-05 10:30:50,565 [analyzer] INFO: Added new file to list with pid 324 and path C:\Windows\System32\vds.exe 2025-05-05 10:30:51,799 [analyzer] INFO: Added new file to list with pid 324 and path C:\Windows\System32\VSSVC.exe 2025-05-05 10:30:53,252 [analyzer] INFO: Added new file to list with pid 324 and path C:\Windows\System32\wbengine.exe 2025-05-05 10:30:54,690 [analyzer] INFO: Added new file to list with pid 324 and path C:\Windows\System32\wbem\WmiApSrv.exe 2025-05-05 10:30:55,940 [analyzer] INFO: Added new file to list with pid 324 and path C:\Program Files\Windows Media Player\wmpnetwk.exe 2025-05-05 10:30:56,642 [analyzer] INFO: Analysis timeout hit, terminating analysis. 2025-05-05 10:30:56,815 [lib.api.process] ERROR: Failed to dump memory of 64-bit process with pid 324. 2025-05-05 10:30:57,174 [analyzer] INFO: Terminating remaining processes before shutdown. 2025-05-05 10:30:57,174 [lib.api.process] INFO: Successfully terminated process with pid 324. 2025-05-05 10:30:57,220 [analyzer] WARNING: File at path u'c:\\windows\\system32\\fxssvc.exe' does not exist, skip. 2025-05-05 10:30:57,220 [analyzer] WARNING: File at path u'c:\\windows\\system32\\wbem\\wmiapsrv.exe' does not exist, skip. 2025-05-05 10:30:57,267 [analyzer] WARNING: File at path u'c:\\windows\\system32\\snmptrap.exe' does not exist, skip. 2025-05-05 10:30:57,392 [analyzer] WARNING: File at path u'c:\\windows\\system32\\vds.exe' does not exist, skip. 2025-05-05 10:30:57,424 [analyzer] WARNING: File at path u'c:\\windows\\system32\\wbengine.exe' does not exist, skip. 2025-05-05 10:30:57,611 [analyzer] WARNING: File at path u'c:\\windows\\system32\\vssvc.exe' does not exist, skip. 2025-05-05 10:30:57,611 [analyzer] WARNING: File at path u'c:\\windows\\system32\\ieetwcollector.exe' does not exist, skip. 2025-05-05 10:30:57,611 [analyzer] WARNING: File at path u'c:\\windows\\system32\\msdtc.exe' does not exist, skip. 2025-05-05 10:30:57,611 [analyzer] WARNING: File at path u'c:\\windows\\system32\\locator.exe' does not exist, skip. 2025-05-05 10:30:57,690 [analyzer] WARNING: File at path u'c:\\windows\\system32\\alg.exe' does not exist, skip. 2025-05-05 10:30:57,690 [analyzer] INFO: Analysis completed.
2025-05-05 11:27:39,879 [cuckoo.core.scheduler] DEBUG: Task #6432968: no machine available yet 2025-05-05 11:27:40,900 [cuckoo.core.scheduler] DEBUG: Task #6432968: no machine available yet 2025-05-05 11:27:42,029 [cuckoo.core.scheduler] DEBUG: Task #6432968: no machine available yet 2025-05-05 11:27:43,094 [cuckoo.core.scheduler] DEBUG: Task #6432968: no machine available yet 2025-05-05 11:27:44,180 [cuckoo.core.scheduler] DEBUG: Task #6432968: no machine available yet 2025-05-05 11:27:45,252 [cuckoo.core.scheduler] DEBUG: Task #6432968: no machine available yet 2025-05-05 11:27:46,458 [cuckoo.core.scheduler] DEBUG: Task #6432968: no machine available yet 2025-05-05 11:27:47,515 [cuckoo.core.scheduler] DEBUG: Task #6432968: no machine available yet 2025-05-05 11:27:48,575 [cuckoo.core.scheduler] DEBUG: Task #6432968: no machine available yet 2025-05-05 11:27:49,652 [cuckoo.core.scheduler] DEBUG: Task #6432968: no machine available yet 2025-05-05 11:27:50,732 [cuckoo.core.scheduler] DEBUG: Task #6432968: no machine available yet 2025-05-05 11:27:51,868 [cuckoo.core.scheduler] DEBUG: Task #6432968: no machine available yet 2025-05-05 11:27:52,964 [cuckoo.core.scheduler] DEBUG: Task #6432968: no machine available yet 2025-05-05 11:27:54,052 [cuckoo.core.scheduler] DEBUG: Task #6432968: no machine available yet 2025-05-05 11:27:55,145 [cuckoo.core.scheduler] DEBUG: Task #6432968: no machine available yet 2025-05-05 11:27:56,342 [cuckoo.core.scheduler] DEBUG: Task #6432968: no machine available yet 2025-05-05 11:27:57,423 [cuckoo.core.scheduler] DEBUG: Task #6432968: no machine available yet 2025-05-05 11:27:58,477 [cuckoo.core.scheduler] DEBUG: Task #6432968: no machine available yet 2025-05-05 11:27:59,521 [cuckoo.core.scheduler] DEBUG: Task #6432968: no machine available yet 2025-05-05 11:28:00,659 [cuckoo.core.scheduler] DEBUG: Task #6432968: no machine available yet 2025-05-05 11:28:01,700 [cuckoo.core.scheduler] DEBUG: Task #6432968: no machine available yet 2025-05-05 11:28:02,880 [cuckoo.core.scheduler] DEBUG: Task #6432968: no machine available yet 2025-05-05 11:28:03,937 [cuckoo.core.scheduler] DEBUG: Task #6432968: no machine available yet 2025-05-05 11:28:05,003 [cuckoo.core.scheduler] DEBUG: Task #6432968: no machine available yet 2025-05-05 11:28:06,081 [cuckoo.core.scheduler] DEBUG: Task #6432968: no machine available yet 2025-05-05 11:28:07,312 [cuckoo.core.scheduler] DEBUG: Task #6432968: no machine available yet 2025-05-05 11:28:08,481 [cuckoo.core.scheduler] DEBUG: Task #6432968: no machine available yet 2025-05-05 11:28:09,530 [cuckoo.core.scheduler] DEBUG: Task #6432968: no machine available yet 2025-05-05 11:28:10,781 [cuckoo.core.scheduler] INFO: Task #6432968: acquired machine win7x6421 (label=win7x6421) 2025-05-05 11:28:10,803 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.221 for task #6432968 2025-05-05 11:28:11,044 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 3026748 (interface=vboxnet0, host=192.168.168.221) 2025-05-05 11:28:23,007 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x6421 2025-05-05 11:28:23,491 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x6421 to vmcloak 2025-05-05 11:30:18,500 [cuckoo.core.guest] INFO: Starting analysis #6432968 on guest (id=win7x6421, ip=192.168.168.221) 2025-05-05 11:30:19,531 [cuckoo.core.guest] DEBUG: win7x6421: not ready yet 2025-05-05 11:30:24,560 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x6421, ip=192.168.168.221) 2025-05-05 11:30:24,648 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x6421, ip=192.168.168.221, monitor=latest, size=6660546) 2025-05-05 11:30:26,267 [cuckoo.core.resultserver] DEBUG: Task #6432968: live log analysis.log initialized. 2025-05-05 11:30:27,337 [cuckoo.core.resultserver] DEBUG: Task #6432968 is sending a BSON stream 2025-05-05 11:30:27,725 [cuckoo.core.resultserver] DEBUG: Task #6432968 is sending a BSON stream 2025-05-05 11:30:28,618 [cuckoo.core.resultserver] DEBUG: Task #6432968: File upload for 'shots/0001.jpg' 2025-05-05 11:30:28,654 [cuckoo.core.resultserver] DEBUG: Task #6432968 uploaded file length: 133483 2025-05-05 11:30:40,757 [cuckoo.core.guest] DEBUG: win7x6421: analysis #6432968 still processing 2025-05-05 11:30:55,876 [cuckoo.core.guest] DEBUG: win7x6421: analysis #6432968 still processing 2025-05-05 11:30:56,931 [cuckoo.core.resultserver] DEBUG: Task #6432968: File upload for 'curtain/1746433856.92.curtain.log' 2025-05-05 11:30:56,937 [cuckoo.core.resultserver] DEBUG: Task #6432968 uploaded file length: 36 2025-05-05 11:30:57,153 [cuckoo.core.resultserver] DEBUG: Task #6432968: File upload for 'sysmon/1746433857.14.sysmon.xml' 2025-05-05 11:30:57,176 [cuckoo.core.resultserver] DEBUG: Task #6432968 uploaded file length: 1472680 2025-05-05 11:30:57,201 [cuckoo.core.resultserver] DEBUG: Task #6432968: File upload for 'files/51b75cfa31f65419_perfhost.exe' 2025-05-05 11:30:57,222 [cuckoo.core.resultserver] DEBUG: Task #6432968 uploaded file length: 1519104 2025-05-05 11:30:57,243 [cuckoo.core.resultserver] DEBUG: Task #6432968: File upload for 'files/a9fda52ef09f461c_aspnet_state.exe' 2025-05-05 11:30:57,278 [cuckoo.core.resultserver] DEBUG: Task #6432968 uploaded file length: 1533952 2025-05-05 11:30:57,306 [cuckoo.core.resultserver] DEBUG: Task #6432968: File upload for 'files/2c7f3547c2374f5d_mscorsvw.exe' 2025-05-05 11:30:57,334 [cuckoo.core.resultserver] DEBUG: Task #6432968 uploaded file length: 1561600 2025-05-05 11:30:57,355 [cuckoo.core.resultserver] DEBUG: Task #6432968: File upload for 'files/c88fcd7aa2c58e4a_wmpnetwk.exe' 2025-05-05 11:30:57,396 [cuckoo.core.resultserver] DEBUG: Task #6432968 uploaded file length: 2106368 2025-05-05 11:30:57,412 [cuckoo.core.resultserver] DEBUG: Task #6432968: File upload for 'files/d7c1278cad7fd1b1_ose.exe' 2025-05-05 11:30:57,434 [cuckoo.core.resultserver] DEBUG: Task #6432968 uploaded file length: 1670144 2025-05-05 11:30:57,447 [cuckoo.core.resultserver] DEBUG: Task #6432968: File upload for 'files/b8bc43fabe9b80d5_flashplayerupdateservice.exe' 2025-05-05 11:30:57,476 [cuckoo.core.resultserver] DEBUG: Task #6432968 uploaded file length: 1762816 2025-05-05 11:30:57,501 [cuckoo.core.resultserver] DEBUG: Task #6432968: File upload for 'files/8903fbaa2aa43df0_ehsched.exe' 2025-05-05 11:30:57,524 [cuckoo.core.resultserver] DEBUG: Task #6432968 uploaded file length: 1625600 2025-05-05 11:30:57,530 [cuckoo.core.resultserver] DEBUG: Task #6432968: File upload for 'files/f7ad4b09afb301ce_dllhost.exe' 2025-05-05 11:30:57,532 [cuckoo.core.resultserver] DEBUG: Task #6432968 uploaded file length: 7168 2025-05-05 11:30:57,564 [cuckoo.core.resultserver] DEBUG: Task #6432968: File upload for 'files/3e1d188d883d8374_mscorsvw.exe' 2025-05-05 11:30:57,605 [cuckoo.core.resultserver] DEBUG: Task #6432968 uploaded file length: 1585152 2025-05-05 11:30:57,616 [cuckoo.core.resultserver] DEBUG: Task #6432968: File upload for 'files/78617ddf9a0067a3_msiexec.exe' 2025-05-05 11:30:57,623 [cuckoo.core.resultserver] DEBUG: Task #6432968 uploaded file length: 73216 2025-05-05 11:30:57,649 [cuckoo.core.resultserver] DEBUG: Task #6432968: File upload for 'files/de94788e62939fba_maintenanceservice.exe' 2025-05-05 11:30:57,664 [cuckoo.core.resultserver] DEBUG: Task #6432968 uploaded file length: 1640960 2025-05-05 11:30:57,682 [cuckoo.core.resultserver] DEBUG: Task #6432968: File upload for 'files/e58d797d88479251_ehrecvr.exe' 2025-05-05 11:30:57,693 [cuckoo.core.resultserver] DEBUG: Task #6432968 uploaded file length: 1276416 2025-05-05 11:30:57,719 [cuckoo.core.resultserver] DEBUG: Task #6432968 had connection reset for <Context for LOG> 2025-05-05 11:30:58,902 [cuckoo.core.guest] INFO: win7x6421: analysis completed successfully 2025-05-05 11:30:58,917 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks 2025-05-05 11:30:58,943 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer 2025-05-05 11:30:59,646 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x6421 to path /srv/cuckoo/cwd/storage/analyses/6432968/memory.dmp 2025-05-05 11:30:59,647 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x6421 2025-05-05 11:34:11,880 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.221 for task #6432968 2025-05-05 11:34:13,790 [cuckoo.core.scheduler] DEBUG: Released database task #6432968 2025-05-05 11:34:13,968 [cuckoo.core.scheduler] INFO: Task #6432968: analysis procedure completed
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Create a windows service | rule | create_service | ||||||
description | Escalade priviledges | rule | escalate_priv | ||||||
description | Affect system registries | rule | win_registry | ||||||
description | Affect system token | rule | win_token | ||||||
description | Affect private profile | rule | win_files_operation |